Reasoning in the Fog

Why Complex Systems Resist the Models We Build to Govern Them

James Wolstencroft · June 2026

The Tekmerium · Foundations

Abstract

Every governance framework rests on an unstated wager: how much of a complex system can be captured in a model and governed through that model alone. Under modern engineering conditions, this paper argues, the wager is routinely lost through a recurring category error that mistakes the formal model for the living system, visible alike in engineering, public administration, planning and medicine. From this, it draws one falsifiable claim, the integration paradox, and a discipline of restraint: knowing not only how to formalise, but where formalisation must stop and tacit judgement begin.

1. The clean diagram is a lie

The clean diagram shows the system, and the fog depicts its changing reality.

Real systems are built under budgets that shrink mid-programme, requirements that drift faster than their baseline, and legacy no living engineer fully understands. The tidy diagram admits none of this. Every governance method makes a wager on how much of that stormy reality a model can govern. When the wager is modest, it pays; when it is absolute, it is lost, and lost the same way every time. How it is lost is what this paper sets out to identify.

2. The category error: the finger and the moon

The root failure is mistaking the model for the thing it describes.

The model belongs to the World of Logic, static and containing only what we put there; the system belongs to the World of the Real, dynamic and indifferent to our diagrams. A model describes a system as a map describes territory: indispensable for travelling, fatal if mistaken for the ground. Once a scheme is treated as the authoritative account rather than as a lossy projection, everything it omits becomes administratively invisible. What it omits is the tacit, context-bound part where the stakes are highest.

3. How formalisation devours itself

Mandated as compliance rather than offered as insight, a model stops serving reasoning and becomes the work itself.

Model-Based Systems Engineering rightly set out to replace scattered documents with a single source of truth, the direction this series takes. But when imposed as a strict regime, it inverted. The goal became producing schema-compliant, audit-ready artefacts. The engineering reasoning it was meant to record withered; the measure was promoted to the goal. We have all done it, I have done it, filled in the compliance matrix at midnight because the review was Friday and the reasoning could wait. This is how any strict framework devours itself, leaving a perfectly documented finger pointing at a moon no one has looked at in months.

4. The same failure everywhere

This is not an engineering quirk but a general failure mode of formalisation.

The same pathology recurs wherever a legible model is imposed on an only-partly-legible reality: in Weber’s rational bureaucracy hardening into an iron cage; in high-modernist city plans that optimised the view from above and bulldozed the street-level web that made districts live; in reductive medicine that isolates the variable and misses the comorbidities and interactions where the real difficulty lives. Each time, the thing the framework cannot see is the thing that decides the outcome.

5. The integration paradox

Individually optimal tools can combine to form a suboptimal system; in other words, excellence in the parts does not add up to excellence in the whole.

The escape from the monolithic method is a federation of best-of-breed tools, each excellent in its domain, yet that configuration is most exposed to failure at the seams. A tiller that needs wet soil and a sower that operates best in the dry are each perfect alone and ruinous in sequence; the failure is invisible at the tool level and shows only at the system level. Engineers call this emergence; the farmer calls it a ruined field. The remedy is neither a single master tool nor merely better parts, but a governance of context that makes each tool’s operating envelope explicit and carries shared meaning across boundaries. This is the series’ central hypothesis, not a settled law.

6. The philosophy of restraint

A mature method is defined as much by what it leaves out as by what it captures.

The lesson of formalisation’s failure is not to capture more but to know where to stop, because the most decisive knowledge is often irreducibly tacit. That is to say, we know more than we can tell, and forcing that knowing into a schema destroys rather than preserves it. The aim is decision support, not decision replacement: carry everything that can genuinely be made explicit and defer to expert judgement where it still outperforms the model. Restraint is not a retreat from rigour but a precondition for it.

7. From documenting to navigating

The architect’s role is to navigate uncertainty, not just document a structure.

A static blueprint becomes outdated as soon as it’s saved; the real challenge is guiding a programme through uncertainty as the conditions move. That means knowing what the system does and why, and knowing how much trust to place in it, which is not the same thing. Two commitments make it possible:

  1. A semantics-first digital thread that links a federated set of tools around shared meaning, such as resolvable identifiers, cross-domain traceability, and configuration management as a first-class concern.

  2. A Digital Backbone above the models that logs decisions, evidence, and confidence levels.

This layer reintroduces the reasoning that was previously removed from artefact creation.

8. Limitations and open problems

The diagnosis carries three risks of its own and names them.

First, restraint can become an alibi for under-specification, dignifying vagueness as respect for judgement.

Second, the integration paradox is a hypothesis inspired by metaphor and recurrence, but it has not been formally defined yet.

Third, and most acute, the remedy is vulnerable to its own error: a Digital Backbone that attaches confidence figures invites mistaking the number for the certainty, the instrument itself becoming a finger mistaken for the moon.

Naming these honestly is part of the restraint the paper recommends.

The ladder of names

The titles elevate both the reader and the system simultaneously.

The reader’s ladder is Greek: aporia, the impasse where the fog is thickest; anagnorisis, the recognition; synergia, the working-in-concert. The system’s ladder ascends through orders of reality: continuity, continuum, hyper-continuum, omnium; the prologue now carries that climb in full. What belongs here is the skill the ladder demands. The architect’s skill is attunement: knowing which order a problem lives in and reaching for the dimension that governs it.

Boundary notes

What this paper establishes, and what it leaves to its companions.

This paper supplies only the case that document-centric governance has failed. The model-centric governance mechanics belong to ‘Breaking the Reconciliation Trap’; the semantic digital thread to ‘Architecting the Connective Substrate’; the Digital Backbone’s provenance and capture-gate to ‘Engineering the Decision Trail; the supplier relationship and validated-model store to ‘Securing the Supplier Ecosystem’ and ‘Governing the Model Vault’; and machine authorship to ‘The Accountable Author’.

References

  • Korzybski, A. Science and Sanity: An Introduction to Non-Aristotelian Systems …

  • Weber, M. Economy and Society. (Rational-legal bureaucracy and the iron cage.)

  • Jacobs, J. The Death and Life of Great American Cities.

  • Scott, J. C. Seeing Like a State: How Certain Schemes to Improve the …

  • Polanyi, M. The Tacit Dimension.

  • Wolstencroft, J. The Continuum. (unpublished at the time of writing)

  • Wolstencroft, J. Breaking the Reconciliation Trap; Securing the Supplier Ecosystem; Architecting the Connective Substrate; Engineering the Decision Trail; Governing the Model Vault; The Accountable Author.